
Illicit OAuth App-Consent Grant: Entra ID Impersonation Campaign
A mass illicit OAuth app-consent campaign against a maritime logistics tenant. Operators register multitenant Entra apps impersonating trusted SaaS brands (iLSMART, Adobe, DocuSign, OneDrive-2025) and send brand-themed consent lures from compromised supplier accounts. Victims who click are screened by a Tycoon antibot redirector into an adversary-in-the-middle relay that proxies the real Entra sign-in, harvests the password, and intercepts the MFA-approved token. The replayed token completes user-level consent grants to the impersonation apps, which read mailboxes over Microsoft Graph, and the attacker registers a new MFA method for durable persistence. Work the Email lures and the Entra consent, sign-in, Graph, and security-info audit to reconstruct the chain.
Launches in 2 days
Tuesday, September 22, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
7 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Sep 22, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free